ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Security.IpLiteral

Contents

Description

A hand-rolled recogniser for IP literals, feeding the internal-range block.

parseIpLiteral turns a host into an IpAddr or Nothing for a DNS name. Its dotted-quad is lenient by design, coercing each octet exactly as inet_aton and hence a libc resolver does, so the policy layer tests the address the proxy would actually dial rather than a decimal misreading. Delegating the recognition to a library would move that boundary, so only range membership goes to iproute, in Ecluse.Core.Security.Host.

Synopsis

IP literals

data IpAddr Source #

An IP literal recognised from a host. The constructors are exported so Ecluse.Core.Security.Host can convert one to an iproute IP value.

Constructors

IpV4 Word8 Word8 Word8 Word8

An IPv4 address as its four octets.

IpV6 [Word16]

An IPv6 address, normalised to its eight 16-bit groups.

parseIpLiteral :: Text -> Maybe IpAddr Source #

Parse a host as an IP literal, or Nothing for a DNS name the host allowlist still constrains: a short inet_aton form (2130706433, 127.1), a bad octet, or a zone id.